Re: [HACKERS] @(#)Mordred Labs advisory 0x0004: Multiple buffer overflows

2002-08-21 Thread Bruce Momjian
Patch applied. Thanks. --- Neil Conway wrote: > Vince Vielhaber <[EMAIL PROTECTED]> writes: > > And another one. > > This patch should fix the problem. Doesn't include my previous patch > for repeat(). Again, somewhat of

Re: [HACKERS] @(#)Mordred Labs advisory 0x0004: Multiple buffer overflows

2002-08-21 Thread Bruce Momjian
Your patch has been added to the PostgreSQL unapplied patches list at: http://candle.pha.pa.us/cgi-bin/pgpatches I will try to apply it within the next 48 hours. --- Neil Conway wrote: > Vince Vielhaber <[EMAIL P

Re: [HACKERS] @(#)Mordred Labs advisory 0x0004: Multiple buffer

2002-08-20 Thread Tatsuo Ishii
> > (That's on a Unicode DB, haven't tested other encodings but AFAICT > > this fix should still work.) > > Is there any chance that pg_database_encoding_max_length() could return > zero That's impossible or at least is the evidence of something badly broken. > and give a divide by zero error?

Re: [HACKERS] @(#)Mordred Labs advisory 0x0004: Multiple buffer overflows in PostgreSQL. (fwd)

2002-08-20 Thread Neil Conway
Vince Vielhaber <[EMAIL PROTECTED]> writes: > On 20 Aug 2002, Neil Conway wrote: > Is there any chance that pg_database_encoding_max_length() could return > zero and give a divide by zero error? Or is that trapped? I don't think so (the array of encodings that contains the data seems to be pre-d

Re: [HACKERS] @(#)Mordred Labs advisory 0x0004: Multiple buffer

2002-08-20 Thread Vince Vielhaber
On 20 Aug 2002, Neil Conway wrote: > Vince Vielhaber <[EMAIL PROTECTED]> writes: > > And another one. > > This patch should fix the problem. Doesn't include my previous patch > for repeat(). Again, somewhat off-the-cuff, so I might have missed > something... > > test=# select lpad('x',1431655

Re: [HACKERS] @(#)Mordred Labs advisory 0x0004: Multiple buffer overflows in PostgreSQL. (fwd)

2002-08-20 Thread Neil Conway
Vince Vielhaber <[EMAIL PROTECTED]> writes: > And another one. This patch should fix the problem. Doesn't include my previous patch for repeat(). Again, somewhat off-the-cuff, so I might have missed something... test=# select lpad('x',1431655765,''); ERROR: Requested length

Re: [HACKERS] @(#)Mordred Labs advisory 0x0004: Multiple buffer overflows inPostgreSQL. (fwd)

2002-08-20 Thread Frank Wiles
.--[ Dann Corbit wrote (2002/08/20 at 14:05:37) ]-- | | ... [large snip] ... | | Well, of course, a well mannered team member would report the bugs | through one of the normal channels. | On the other hand, a malicious tester who finds these problems performs | two valuable

Re: [HACKERS] @(#)Mordred Labs advisory 0x0004: Multiple buffer overflows inPostgreSQL. (fwd)

2002-08-20 Thread Dann Corbit
> -Original Message- > From: Frank Wiles [mailto:[EMAIL PROTECTED]] > Sent: Tuesday, August 20, 2002 1:57 PM > To: Dann Corbit > Cc: [EMAIL PROTECTED] > Subject: Re: [HACKERS] @(#)Mordred Labs advisory 0x0004: > Multiple buffer overflows inPostgreSQL. (fwd) > &g

Re: [HACKERS] @(#)Mordred Labs advisory 0x0004: Multiple buffer overflows in PostgreSQL. (fwd)

2002-08-20 Thread Tom Lane
Vince Vielhaber <[EMAIL PROTECTED]> writes: > And another one. Sure would be nice if shit-for-brains would mention > it to us first. I don't even mind the "first" part, but it would certainly be polite of him to cc: pghackers rather than expecting us to dig it off bugtraq. But, as someone else

Re: [HACKERS] @(#)Mordred Labs advisory 0x0004: Multiple buffer overflows inPostgreSQL. (fwd)

2002-08-20 Thread Dann Corbit
> -Original Message- > From: Vince Vielhaber [mailto:[EMAIL PROTECTED]] > Sent: Tuesday, August 20, 2002 1:48 PM > To: [EMAIL PROTECTED] > Subject: [HACKERS] @(#)Mordred Labs advisory 0x0004: Multiple > buffer overflows inPostgreSQL. (fwd) > > > > And an

[HACKERS] @(#)Mordred Labs advisory 0x0004: Multiple buffer overflows inPostgreSQL. (fwd)

2002-08-20 Thread Vince Vielhaber
And another one. Sure would be nice if shit-for-brains would mention it to us first. Vince. -- == Vince Vielhaber -- KA8CSHemail: [EMAIL PROTECTED]http://www.pop4.net 56K Nationwide Dialup from $16.00/mo a